Tag
#Plugin Vulnerability
Unauthenticated Remote Code Execution Vulnerability in ProfilePress WordPress Plugin
The ProfilePress WordPress plugin before version 4.17.2 is vulnerable to unauthenticated remote code execution. This vulnerability allows attackers to install and activate arbitrary plugins, potentially leading to PHP code execution as the web-server user. The vulnerability has a CVSS score of 8.1, indicating high severity.
Understanding and Defending Against CVE-2026-19718: Weak Secret Generation in WordPress Plugins
CVE-2026-19718 is a high-severity vulnerability affecting several WordPress plugins, including BlogVault Backup & Staging, MalCare WordPress Security Plugin, and The WP Remote WordPress Plugin. The vulnerability allows unauthenticated attackers to obtain data derived from a secret binding a site to its remote management service, which is generated using a weak pseudo-random number generator. This enables attackers to recover the secret and gain administrative access to the site. The vulnerability has a CVSS score of 8.1 and is considered high severity.
CVE-2026-15001: Privilege Escalation in bLoyal: Loyalty & Promotions by bLoyal WordPress Plugin
The bLoyal: Loyalty & Promotions by bLoyal WordPress plugin is vulnerable to Privilege Escalation (CVE-2026-15001, CVSS 8.8) in all versions up to 3.1.611.78. Authenticated attackers with Subscriber-level access can exploit this vulnerability to escalate privileges to Administrator, potentially leading to full site compromise. Immediate patching is recommended.
CVE-2026-14829: Unauthenticated License Deactivation in Checkimate WordPress Plugin
The Checkimate — WooCommerce Checkout, Abandoned Cart Recovery & Order Bumps WordPress plugin through 1.0.13 has a vulnerability allowing unauthenticated attackers to deactivate the plugin's premium licensing state and erase the stored license key. This vulnerability has a CVSS score of 8.2, indicating high severity. Affected users should update to a patched version.